Accredited and recognised


Why the same certificate costs £300 or £700
Cyber Essentials is a single scheme with a single set of requirements, run by IASME on behalf of the NCSC. The certificate you get from the cheapest certification body and the dearest one is the same certificate, worth the same in a tender, accepted identically by an insurer.
So the spread is not about the certificate. It is about how much of the work somebody else does, and about how much margin the seller takes on top of the assessment fee.
| Roughly | What that buys | Who it suits |
|---|---|---|
| £300 to £400 | The assessment itself. You complete the questionnaire, an assessor reviews it, you get the certificate on a pass | Anyone whose controls already meet the standard |
| £400 to £600 | The assessment plus a check of your setup before you submit, so you are not guessing | Most organisations doing it for the first time |
| £600 to £1,200 | The assessment plus consultancy: someone goes through the questions with you, often remediating as they go | Organisations with no internal IT and a mixed estate |
| £1,200 and up | Usually a platform subscription with the certificate bundled in, billed annually | Organisations that want ongoing monitoring, not just the badge |
None of these is wrong. Paying £1,100 for hand-holding you genuinely need is a better outcome than paying £320 and failing twice. The mistake is paying for a tier you do not need, and the opposite mistake is buying the cheapest thing on a estate that is nowhere near ready.
Where our price sits, and why
Cyber Essentials from us is £320 + VAT for a micro organisation of one to nine staff, £440 for ten to forty-nine, £500 for fifty to two hundred and forty-nine, and £600 for two hundred and fifty or more. That is the IASME tier price. We are an appointed Certification Body, so the assessment fee goes through us rather than to a reseller, and we do not mark it up.
Two optional add-ons, both genuinely optional. A gap analysis at £300, where we look at your setup against the five controls before you answer anything and tell you what will fail. Urgent turnaround at £100, which moves you to the front of the assessment queue for a same-day review where your submission arrives before midday.
If you tick all five boxes in the tool above, buy the bare assessment and ignore both.
Ticked all five in the check above? Then you need the certificate and nothing else.
The saving that costs you more
Cyber Essentials is pass or fail. There is no partial credit and no negotiating. If your submission does not meet the five controls you do not get a certificate that day at any price, and what happens instead is a feedback cycle: the assessor tells you what failed, you fix it, you resubmit.
Under the current scheme rules you get one free resubmission within a limited window. Miss the window, or fail a second time, and you are paying the assessment fee again and starting over.
So the arithmetic on skipping a £300 gap analysis is not "save £300". It is "save £300, or spend another £320 plus three weeks and miss the deadline that made you buy it". On an estate you already run properly, the first outcome is overwhelmingly likely and you should skip it. On one you inherited last quarter with unmanaged laptops and half the cloud services missing multi-factor authentication, it is not.
Five ways to genuinely reduce what you pay
- Scope honestly, but scope tightly. The scope is everything that touches organisational data. A subsidiary that shares nothing, a segregated network with no route to your data, or a set of test devices that never touch live systems can legitimately sit outside it. Whole-organisation scope is the default and it is not always the right one.
- Fix the three obvious things first. Unsupported software still in use, multi-factor authentication missing on a cloud service, and everyday accounts with local administrator rights. Those three account for most first-time failures and all three are free to fix.
- Read the questions before you buy. IASME publishes the self-assessment questions. Reading them takes an hour and tells you your real timeline better than any provider's turnaround claim.
- Do not buy the platform if you only want the certificate. A subscription with monitoring bundled in is good value if you will use the monitoring. If you want the badge for a tender, you are paying an annual fee for a one-off need.
- Do not pay separately for what the certification body already includes. Ask what happens on a fail, whether a resubmission is included, and whether support during the assessment is chargeable. Those three answers move the real total more than the headline price does.
What we will not do to make a price look lower
We will not review a submission with a model instead of a person. Every assessment is reviewed by a qualified, certified assessor, which is slower and more expensive than the alternative and is the entire point of the scheme.
We will not quote a fee that excludes something you will certainly need and mention it afterwards. The prices above are the prices.
And we will not tell you that you need the gap analysis when the tool above says you do not. Selling help to somebody who does not need it is how the middle of that price table got so crowded.
When cheap is the wrong question
If a client, insurer or tender has asked for Cyber Essentials Plus, price comparison on the basic certificate is beside the point. Plus is a hands-on technical audit by an assessor rather than a reviewed self-assessment, it needs a valid Cyber Essentials certificate less than three months old as a prerequisite, and it costs several times as much. We assess Plus from late October 2026.
And if what you actually need is to know whether your systems can be broken into, Cyber Essentials does not tell you that. It tells you five baseline controls are in place. That is worth having and it is not a penetration test.
Are you paying for something you do not need?
Tick what is true of your organisation. The more you tick, the less help you need buying and the closer you should be to the bottom of the price range.
Further reading on this site
Four guides going deeper than this page does. All free, no sign-up.
- What Cyber Essentials costs you beyond the assessment feeFour organisations can pay the same assessment fee and spend anywhere between nothing and several thousand pounds getting to the point of paying it. Here is where that money goes.
- Seven days, no spend, and a submission you can defendMost first-time failures are caused by four or five things, all of which you can find yourself with nothing but your own time. Here is the order to look in.
- Cyber Essentials is not a purchase, it is a subscription to a standardAlmost every organisation budgets for the first certificate and almost none budget for the fourth. The arithmetic is not difficult; it is just rarely done.
- A low price is fine. Not knowing what it contains is notThere is nothing wrong with paying less. There is quite a lot wrong with finding out after you have paid that the price covered a different thing from the one you thought.